CVE-2023-41164

Name
CVE-2023-41164
Description
In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://www.djangoproject.com/weblog/2023/sep/04/security-releases/
MISC https://docs.djangoproject.com/en/4.2/releases/security/
MISC https://groups.google.com/forum/#!forum/django-announce
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HJFRPUHDYJHBH3KYHSPGULQM4JN7BMSU/
https://groups.google.com/forum/#%21forum/django-announce
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HJFRPUHDYJHBH3KYHSPGULQM4JN7BMSU/
cve@mitre.org https://security.netapp.com/advisory/ntap-20231214-0002/
cve@mitre.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQJOMNRMVPCN5WMIZ7YSX5LQ7IR2NY4D/
af854a3a-2127-422b-91ae-364da2661108 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZQJOMNRMVPCN5WMIZ7YSX5LQ7IR2NY4D/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* django >= 4.2 < 4.2.5
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* django >= 4.1 < 4.1.11
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* django >= 3.2 < 3.2.21

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
py3-django edge-community 4.2.5-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
py3-django 3.22-community 4.2.5-r0 None fixed
py3-django 3.21-community 4.2.5-r0 None fixed
py3-django 3.20-community 4.2.5-r0 None fixed
py3-django 3.19-community 4.2.5-r0 None fixed
py3-django 3.18-community 4.2.5-r0 Natanael Copa <ncopa@alpinelinux.org> fixed